• Onno (VK6FLAB)
    link
    fedilink
    English
    4613 hours ago

    I’m sorry, but has no-one heard of https://letsencrypt.org that issues certificates via API for free?

    I would not be surprised if certificates at some point will be issued for each session.

    • @[email protected]
      link
      fedilink
      English
      42 hours ago

      It’s not the issuance that’s the headache, it’s the installation. There are more things that need valid certs than just webservers

      • @[email protected]
        link
        fedilink
        English
        02 hours ago

        Certbot is basically automatic, think mines on a cronjob now.

        Who actually does this shit manually?

        • @[email protected]
          link
          fedilink
          English
          425 minutes ago

          Any number of numerous appliances and hideously malformed business systems that don’t have ways to automate cert changes.

          Not everyone gets to work in their simple little world of standards-following lab servers.

    • Antithetical
      link
      fedilink
      English
      5712 hours ago

      I’m sorry, but have you ever needed to manage some certificates for a legacy system or something that isn’t just a simple public facing webserver?

      Automation becomes complicated very quickly. And you don’t want to give DNS mutation access to all those systems to renew with DNS-01.

      • @[email protected]
        link
        fedilink
        English
        319 hours ago

        Ahh yes the: we can’t have self signed certificates for security reasons but also can’t open up the environment to the web, and we dont have our own CA server, trifecta.

        Solution: awkward, manual, certificate import process from a 3rd party vendor.

        • @[email protected]
          link
          fedilink
          English
          148 hours ago

          Even if you have an internal CA, few appliances support this kind of automation. At best, they have an API, and you get to write that automation yourself for each appliance.

          • @[email protected]
            link
            fedilink
            English
            66 hours ago

            Knew a place where, for some devices, it was only available via a web interface. It was automated via WebDriver by a sysadmin that was losing his mind.

        • Antithetical
          link
          fedilink
          English
          1411 hours ago

          Yes, and that is where we enter the complicated territories…

            • @[email protected]
              link
              fedilink
              English
              337 minutes ago

              If you think it’s just too easy but people are still discussing it, please entertain the notion that you may have oversimplified the situation in your assessment and that as assumptions become clarified you may yet soon understand a horror that apple can’t quite grok.